Showing posts with label Bug Bounty. Show all posts
Showing posts with label Bug Bounty. Show all posts

Facebook HTML Injection

03:13 Posted by Ali Hassan Ghori ,

Found a Bug in Facebook 

Hello,
I discovered a Html Injection in m.facebook.com.
Here is a Vulnerable Page.
 
  
I changed the value of parameter error , to Bug Found By ALi Hasan Ghauri

Link:https://m.facebook.com/pages/boosted_post/?pid=154728514671464&sid=317138311763816&
error=Bug%20Found%20By%20ALi%20Hasan%20Ghauri


 Now See


Facebook accepted this bug.


And The Bounty Reward




Thanks Facebook Security Team !!!

 

Ali Hasan Ghauri In Wizehive Special_Thanks Page !

10:01 Posted by Ali Hassan Ghori ,
Well , WizeHive empowers people to get customized business applications up and running in under an hour. These business applications gather any type of data and get work done efficiently.


WizeHive is honored to spotlight the Reearchers for their contributions in making WizeHive safer and their actions benefit the thousands of people who rely on WizeHive every day.

Ali Hasan Ghauri In Wizehive Special_Thanks Page :

http://www.wizehive.com/special_thanks.html

Wizehive-special_thanks-ali-hasan-ghauri


He Got this by reporting two Cross Site Scripting to them :

Wizehive-special_thanks-ali-hasan-ghauri

Wizehive-special_thanks-ali-hasan-ghauri


ALHAMDULILLAH !

"Grand Stand 4" [Design for Trade Fair Stands] worth € 69.00 | ALHAMDULILLAH !

09:34 Posted by Ali Hassan Ghori ,
Hi Every One ,

Today is the Awesome Day , Because i just received a 3.0 Kg of Book "Grand Stand 4" [Design for Trade Fair Stands] worth € 69.00 as a reward from Frameweb.com . I was reported some Vulnerabilities to them . Then they replied me (as shown in Screen Shot) .


AHPT ALi Hasan Ghauri Best and Expert in Web Application Security .

Have a Look .


Grand-Stand-4 Ali Hasan Ghauri

Here's the Link : http://www.frameweb.com/books/grand-stand-4


And a Caption.

Frameweb-Books

The weight of this Book is 3.0 Kg and this Book is the latest title in the Grand Stand series presents recent developments in the ever-changing world of stand design.

Ali Hasan Ghauri
Grand-Stand-4


Thanks to the Frameweb Team

ALHAMDULILLAH ! Got T-shirt + $200 Gift Card from Odesk

03:51 Posted by Ali Hassan Ghori ,
ASSALAM O ALAIKUM !

Today , I received Odesk T-shirt + $200 Gift Card From Odesk . I was reported Bug to Odesk .
 Below is Screen Shot of my report to Odesk 


 So They Fixed it and rewarded  me with Odesk  " T-Shirt " and " $200 Thank You Gift Card " 
Here is Screen Shot of my Gift 

Listed In CoinBase White Hat Award List !

22:10 Posted by Ali Hassan Ghori ,
I found some bugs on coinbase and reported to coinbase Security Team . They fix this Bugs and Listed my name in Coinbase Award List . Bug Bounty , Decisions on future award payouts will be made at a later date.

Listed In CoinBase White Hat Award List !Ali hasan Ghauri
Listed In CoinBase White Hat Award List !

Got Contribution on BugCrowd

00:33 Posted by Ali Hassan Ghori ,
Got Contribution on BugCrowd !

I was reported some new Websites , who have Bug Bounty Program or Hall Of Fame Program . BugCrowd Updated it on ( http://bugcrowd.com/list-of-bug-bounty-programs/ ) Page .

Thanks BugCrowd Team !

Got Contribution on BugCrowd !  I was reported some new Websites , who have Bug Bounty Program or Hall Of Fame Program . BugCrowd Updated it on ( http://bugcrowd.com/list-of-bug-bounty-programs/ ) Page .  Thanks BugCrowd Team !   ALHAMDULILLAH !  Thanks Of ALLAH ALMIGHTY


 ALHAMDULILLAH !

Thanks Of ALLAH ALMIGHTY

Listed as Responsible disclosure in wizehive.com

18:42 Posted by Ali Hassan Ghori ,
WizeHive is honored to spotlight the following people for their contributions in making WizeHive safer. Members of this list reported significant bugs or security concerns, and their actions benefit the thousands of people who rely on WizeHive every day.

Ali Hasan Ghauri (@alihasanghauri)

On behalf of the WizeHive team and users worldwide, thank you. 

ChinaBuye Gives " Ali Hasan Ghauri "(AHPT) 500 Points For reporting Some Bugs .

19:06 Posted by Ali Hassan Ghori ,
China Buye Gives Me 500 Points For reporting Some Bugs .

i can buy Redeem Things with this Points .

I already bought a Watch at 251 Points !!! Waiting for receiving .

My remaining Points is 249 , !!! I enjoying !!!

Now it's Your turn . Keep Trying for finding bugs on http://www.chinabuye.com/ .
 
 

Security Researchers Acknowledgment

19:41 Posted by Ali Hassan Ghori , ,
Facebook - White Hats
https://www.facebook.com/whitehat/

Twitter - Twitter Whitehats 2012 & 2013
https://twitter.com/about/security

Google - Security Hall of Fame - Honorable Mention - "April - June 2011"
http://www.google.com/about/appsecurity/hall-of-fame/distinction/

Tuenti - Security Hall of Fame
http://corporate.tuenti.com/en/dev/hall-of-fame

Nokia Siemens Networks - Security Hall of Fame - "November 2012"
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure

Constant Contact - Security Acknowledgement
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp

OwnCloud - Security Hall of Fame 2012 & 2013
http://owncloud.org/security/hall-of-fame/

iFixit - Security Acknowledgement 2012 & 2013
http://www.ifixit.com/Info/responsible_disclosure

Zynga - Whitehats 2012 & 2013
http://company.zynga.com/security/whitehats

Redhat - Vulnerability Acknowledgements for Redhat online services -"2012 Acknowledgements"
https://access.redhat.com/knowledge/articles/66234

Adobe - Security Acknowledgments
http://www.adobe.com/support/security/bulletins/securityacknowledgments.html

SoundCloud - Whitehat Thanks List
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure

GitLab - Vulnerability Acknowledgements
http://blog.gitlab.com/vulnerability-acknowledgements/

Collective Idea - HarmonyApp Security Thank-you List
http://get.harmonyapp.com/security/

Bug Bounty Programs

07:55 Posted by Ali Hassan Ghori
List of Bug Bounty Programs
Bug Bounty Program a well known topic is on the heat these days, known companies like: google, Facebook, Mozilla are paying for finding a vulnerabilities on their web servers, products, services or some associated applications. Here is a list for all the Security Researchers and Bug Hunters to target all the best :)

Bug Bounty Websites for Web Application Vulnerability
Mozilla

security@mozilla.org
http://www.mozilla.org/security
http://www.mozilla.org/projects/security/security-bugs-policy.html
http://www.mozilla.org/security/announce

Google
security@google.com
https://www.google.com/appserve/security-bugs/new?rl=xkp7zert49a5q6owod28bhr2

Facebook
http://www.facebook.com/whitehat/bounty

Paypal

sitesecurity@paypal.com
https://cms.paypal.com/cgi-bin/marketingweb?cmd=_render-content&content_ID=security/reporting_security_issues

Etsy
http://www.etsy.com

Wordpress
http://www.whitefirdesign.com/about/wordpress-security-bug-bounty-program.html

Commonsware
http://commonsware.com/bounty.html

CCBill
http://www.ccbill.com/developers/security/vulnerability-reward-program.php
http://www.ccbill.com/developers/security/rewards.php

Vark
http://www.vark.com

Windthorstisd

http://www.windthorstisd.net/BugReport.cfm


Bug Bounty Websites for Products Vulnerability
Mozilla

http://www.mozilla.org/security
http://www.mozilla.org/security/known-vulnerabilities/firefox.html

Google Chrome
http://www.chromium.org/Home/chromium-security/vulnerability-rewards-program

Zero Day Initiative
http://www.zerodayinitiative.com

Barracuda
bugbounty@barracuda.com
http://www.barracudalabs.com/bugbounty
http://www.barracudalabs.com/bugbounty/halloffame.html

Artifex Software
http://www.ghostscript.com/Bug_bounty_program.html

Hex Rays
http://www.hex-rays.com/bugbounty.shtml

Ardour
http://ardour.org/bugbounty

Piwik
http://piwik.org/security


Hall of Fame & Responsible Disclosure Websites(No Bounties)

Microsoft
http://technet.microsoft.com/en-us/security/ff852094.aspx
http://technet.microsoft.com/en-us/security/cc308589
http://technet.microsoft.com/en-us/security/cc308575
http://technet.microsoft.com/en-us/security/cc261624
http://www.microsoft.com/security/msrc/default.aspx

Apple
product-security@apple.com
http://support.apple.com/kb/HT1318
https://ssl.apple.com/support/security/

Adobe

http://www.adobe.com/support/security/bulletins/securityacknowledgments.html
http://www.adobe.com/support/security/alertus.html

IBM
http://www-03.ibm.com/security/secure-engineering/report.html

Twitter

https://twitter.com/about/security
http://support.twitter.com/groups/33-report-abuse-or-policy-violations/topics/122-reporting-violations/articles/477159-how-to-report-xss-api-and-other-security-vulnerabilities#
https://support.twitter.com/forms

Dropbox
security@dropbox.com
https://www.dropbox.com/security
https://www.dropbox.com/special_thanks

Cisco
http://tools.cisco.com/security/center/home.x#~alerts

Moodle
http://moodle.org/security

Drupal
http://drupal.org/security-team

Oracle

http://www.oracle.com/us/support/assurance/reporting/index.html

Symantec

http://www.symantec.com/security

Ebay

http://pages.ebay.com/securitycenter/Researchers.html

Twilio
http://www.twilio.com/blog/2012/03/reporting-security-vulnerabilities.html

37 Signals

http://37signals.com/security-response

Salesforce
http://www.salesforce.com/company/privacy/disclosure.jsp

Reddit
http://code.reddit.com/wiki/help/whitehat

Github
http://help.github.com/responsible-disclosure/

Ifixit
http://www.ifixit.com/Info/responsible_disclosure

Constant Contact
http://www.constantcontact.com/about-constant-contact/security/report-vulnerability.jsp

Zeggio

http://www.zeggio.com

Simplify
http://simplify-llc.com/simplify-security.html

Team Unify

http://www.teamunify.com/__corp__/security.php

Skoodat
http://www.skoodat.com/Security

Relaso
http://relaso.com/disclosure

Moduscsr
http://www.moduscsr.com/security_statement.php

Cloudnetz
http://cloudnetz.com/Legal/vulnerability-testing-policy.html

Emptrust
http://www.emptrust.com/Security.aspx

Apriva
http://www.apriva.com/security

Amazon
http://aws.amazon.com/security/vulnerability-reporting

SqaureUp
https://squareup.com/security/levels

G-Sec
http://www.g-sec.lu/responsible.disclosure.policy.html

Xen
http://www.xen.org/projects/security_vulnerability_process.html

Engine Yard
http://www.engineyard.com/legal/responsible-disclosure-policy

Lastpass
https://lastpass.com/support_security.php

RedHat
https://access.redhat.com/knowledge/articles/66234

Acquia
https://www.acquia.com/how-report-security-issue

Mahara
security@mahara.org
https://wiki.mahara.org/index.php/Security


Zynga

security@zynga.com
http://company.zynga.com/security/whitehats

Risk.io
https://www.risk.io/security

Opera
http://www.opera.com/security/policy

Owncloud
http://owncloud.org/security/policy
http://owncloud.org/security/hall-of-fame

Scorpion Soft
security@scorpionsoft.com
http://www.scorpionsoft.com/company/disclosurepolicy

Cpaperless

http://www.cpaperless.com/securitystatement.aspx

Wizehive
http://www.wizehive.com/security

Tuenti
http://corporate.tuenti.com/en/dev/hall-of-fame

Nokia Siemens
http://www.nokiasiemensnetworks.com/about-us/responsible-disclosure

Sound Cloud
http://help.soundcloud.com/customer/portal/articles/439715-responsible-disclosure

HTC
http://www.htc.com/us/legal/product-security

Neohapsis

http://www.neohapsis.com/disclosure.php

Puppetlabs
http://puppetlabs.com/security

Norada
http://norada.com/norada/crm/security_response